[Samba] VS: Potential bug in winbindd - Samba

This is a discussion on [Samba] VS: Potential bug in winbindd - Samba ; Hey,
I have a problem with the winbind daemon, while it succesfully authenticates and gets most information, some groups that shouldn't be empty are empty (including "Domain Users"), and some groups that contain other groups (that are empty), only contain ...

[Samba] VS: Potential bug in winbindd

Hey,

I have a problem with the winbind daemon, while it succesfully authenticates and gets most information, some groups that shouldn't be empty are empty (including "Domain Users"), and some groups that contain other groups (that are empty), only contain the users added plainly.

The server is connecting to an AD in ADS mode, Samba version is Version 3.0.23c-2.el5.2, as part of CentOS 5 (RHEL5).

Re: [Samba] VS: Potential bug in winbindd

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Rasmus Larsen wrote:
> Hey,
>
> I have a problem with the winbind daemon, while it
> succesfully authenticates and gets most information, some
> groups that shouldn't be empty are empty (including "Domain
> Users"), and some groups that contain other groups (that are
> empty), only contain the users added plainly.

Known issues. Retrieving member ship of domain users has to
be done using ranged retrieval. Expanding nested domain group
membership is a yet to be done feature.

iD8DBQFGJPMcIR7qMdg1EfYRAvuEAJ9P1+K67ZHJw9W7xkUghv l3nHLGZwCgiqGo
6tU2cdDllvUlWqy5U6dE5zw=
=CsT1
-----END PGP SIGNATURE-----
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba

SV: [Samba] VS: Potential bug in winbindd

Thanks,

Is there any documentation on how to set that up? I've been looking around a bit, but I can't seem to find any.

Rasmus Larsen wrote:
> Hey,
>
> I have a problem with the winbind daemon, while it
> succesfully authenticates and gets most information, some
> groups that shouldn't be empty are empty (including "Domain
> Users"), and some groups that contain other groups (that are
> empty), only contain the users added plainly.

Known issues. Retrieving member ship of domain users has to
be done using ranged retrieval. Expanding nested domain group
membership is a yet to be done feature.

iD8DBQFGJPMcIR7qMdg1EfYRAvuEAJ9P1+K67ZHJw9W7xkUghv l3nHLGZwCgiqGo
6tU2cdDllvUlWqy5U6dE5zw=
=CsT1
-----END PGP SIGNATURE-----
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba

Re: SV: [Samba] VS: Potential bug in winbindd

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Rasmus Larsen wrote:
>>> Hey,
>>>
>>> I have a problem with the winbind daemon, while it
>>> succesfully authenticates and gets most information, some
>>> groups that shouldn't be empty are empty (including "Domain
>>> Users"), and some groups that contain other groups (that are
>>> empty), only contain the users added plainly.
>>>
>> Known issues. Retrieving member ship of domain users has to
>> be done using ranged retrieval. Expanding nested domain group
>> membership is a yet to be done feature.
>
> Is there any documentation on how to set that up? I've
> been looking around a bit, but I can't seem to find any.

They are both bugs in Winbind. What specific pain
are they causing you? I need a reproducible test case
where a real application fails.

iD8DBQFGJ3Y6IR7qMdg1EfYRAhx3AKDeAmMUTKWfE5jUxMHGTx 8zuL/PiQCg480B
lGpacnPWsk8NggGzwmPo9rU=
=Z6iY
-----END PGP SIGNATURE-----
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba